98 Commits

Author SHA1 Message Date
J0WI
9d23763439 main/apache2: security upgrade to 2.4.39 2019-04-03 15:40:36 +00:00
Simon Frankenberger
be9c8ed89d main/apache2: Create /run folder for apache2 on install
The directory /run/apache2 is only created when running in openrc (see
apache2.initd). When installing on a non-openrc system (e.g. docker),
this folder is missing and apache2 refuses to start.

Closes https://bugs.alpinelinux.org/issues/9982
2019-02-14 23:39:16 +02:00
Kaarle Ritvanen
aa1a70d7d2 main/apache2: fix mod_proxy default configuration
fixes #9829
2019-02-01 19:01:05 +02:00
J0WI
e82176fd8b main/apache2: security upgrade to 2.4.38
fixes #9906
2019-01-25 21:34:59 +02:00
J0WI
15b3529d6a main/apache2: modernize APKBUILD 2019-01-25 21:32:58 +02:00
Natanael Copa
4e53775211 main/apache2: rebuild against openssl 1.1 2018-11-07 16:46:10 +00:00
Andy Postnikov
4a7f6f1bf0 main/apache2: upgrade to 2.4.37 2018-10-25 10:07:56 +00:00
Andy Postnikov
f6d1356e60 main/apache2: security upgrade to 2.4.35 (CVE-2018-11763)
fixes #9577
2018-10-25 10:07:45 +00:00
J0WI
d2bfb22c8e main: (Bulk change) Update source urls to https using HTTPS Everywhere 2018-10-06 17:10:04 +00:00
Andy Postnikov
426610a910 main/apache2: security upgrade to 2.4.34 2018-08-17 13:55:20 +00:00
Natanael Copa
cd09307fe3 main/apache2: rebuild against libressl-2.7 2018-04-06 05:19:23 +00:00
Kaarle Ritvanen
fc2557dadf main/apache2: security upgrade to 2.4.33 2018-03-27 14:28:16 +03:00
Jakub Jirutka
63f5e7d295 [various]: unify names of licenses according to SPDX
This commit updates $license variable in all APKBUILDs to comply with
short names specified by SPDX version 3.0 [1] where possible. It was
done using find-and-replace method on substrings inside $license
variables.

Only license names were updated, not "expressions" specifying relation
between the licenses (e.g. "X and Y", "X or Y", "X and (Y or Z)") or
exceptions (e.g. "X with exceptions").

Many licenses have a version or multiple variants, e.g. MPL-2.0,
BSD-2-Clause, BSD-3-Clause. However, $license in many aports do not
contain license version or variant. Since there's no way how to infer
this information just from abuild, it were left without the variant
suffix or version, i.e. non SPDX compliant.

GNU licenses (AGPL, GFDL, GPL, LGPL) are especially complicated. They
exist in two variants: -only (formerly e.g. GPL-2.0) and -or-later
(formerly e.g. GPL-2.0+). We did not systematically noted distinguish
between these variants, so GPL-2.0, GPL2, GPLv2 etc. may mean
GPL-2.0-only or GPL-2.0-or-later. Thus GNU licenses without "+" (e.g.
GPL2+) were left without the variant suffix, i.e. non SPDX compliant.

Note: This commit just fixes format of the license names, no
verification has been done if the specified license information is
actually correct!

[1]: https://spdx.org/licenses/
2017-12-30 21:05:50 +01:00
Natanael Copa
800d524912 main/apache2: rebuild against libressl-2.6 2017-11-09 19:58:33 +00:00
Kaarle Ritvanen
4435a760f3 main/apache2: upgrade to 2.4.29 2017-10-23 23:40:33 +03:00
Kaarle Ritvanen
933cdbb71e main/apache2: upgrade to 2.4.28 2017-10-10 11:40:39 +03:00
Kaarle Ritvanen
2327807882 main/apache2: subpackage for apachectl
ref #5505
2017-09-21 12:06:50 +03:00
Daniel Isaksen
3e84f75e86 main/apache2: fix CVE-2017-9798 aka Optionsbleed 2017-09-21 05:04:20 +00:00
Kaarle Ritvanen
ab8ceb2613 main/apache2: upgrade to 2.4.27 2017-07-10 15:27:01 +03:00
Kaarle Ritvanen
c930c29f44 main/apache2: security upgrade to 2.4.26
fixes #7463
2017-07-06 14:26:18 +03:00
Natanael Copa
8ebdb5403c main/apache2: rebuild against libressl 2.5 2017-04-18 20:45:31 +00:00
Kaarle Ritvanen
ad0a795521 main/apache2: remove obsolete patch 2017-03-06 13:41:08 +02:00
Andy Postnikov
57ba71e078 main/apache2: upgrade to 2.4.25
Security release http://www.apache.org/dist/httpd/CHANGES_2.4.25
Also it includes previous patch for httpoxy
2016-12-27 09:35:24 +02:00
Kaarle Ritvanen
fbaa29e60d main/apache2: generate simple module config files
fixes #6099
fixes #6100
2016-11-04 18:31:38 +02:00
Kaarle Ritvanen
173f86aa76 main/apache2: utils: depend on lynx
fixes #5505
2016-11-04 12:22:49 +02:00
Timo Teräs
ade3338882 main/[various]: set proper arch
fixes commit "main/[various]: dont set arch in split function"
2016-11-01 09:19:40 +02:00
Kaarle Ritvanen
45fa9ece3e main/apache2: adjust genrsa options
increase key length to 2048 bits
remove 'rand' option (not supported by libressl)
2016-10-30 18:44:39 +02:00
Natanael Copa
75ad2ca27e main/[various]: dont set arch in split function 2016-10-26 20:46:53 +00:00
Natanael Copa
0b83baa024 main/apache2: use openssl binary from libressl 2016-10-11 14:14:02 +02:00
Natanael Copa
d68cba99ea main/apache2: rebuild against libressl 2016-10-10 12:04:03 +00:00
Kaarle Ritvanen
f89a084d79 main/apache2: http2.conf 2016-08-14 23:33:23 +03:00
Kaarle Ritvanen
6b670dee84 main/apache2: enable http2 2016-08-14 23:24:50 +03:00
Natanael Copa
88f74f8756 main/apache2: rebuild against perl 5.24 2016-07-27 16:52:02 +00:00
Natanael Copa
23afbfbed7 main/apache2: security fix for CVE-2016-5387
fixes #5925
2016-07-20 13:05:48 +00:00
Christian Kampka
5da78ee6a7 main/apache2: new upstream version 2.4.23 2016-07-06 14:22:33 +02:00
Przemyslaw Pawelczyk
a643ff53e5 main/apache2: Bump pkgrel. 2016-06-29 09:48:24 +00:00
Przemyslaw Pawelczyk
7fd6410222 main/apache2: Reorder install entries in APKBUILD.
Just for consistency with what's in other packages's APKBUILDs.
2016-06-29 09:48:24 +00:00
Przemyslaw Pawelczyk
acfb821e3d main/apache2: Unify .pre-upgrade with .pre-install.
apache2.pre-upgrade now links to apache2.pre-install.

It's not something we want to do for all packages in master (edge).
apache2 already had .pre-upgrade script (ensuring www-data group
existence and making apache user a member of it), which is what existing
.pre-install script also does, so this kind of unification is fine here.

In most other cases linking .pre-upgrade to .pre-install should happen
only in 3.4-stable branch.
2016-06-29 09:48:24 +00:00
Przemyslaw Pawelczyk
511bd7a7a0 main/[various]: Bump pkgrel for .pre-install scripts fixes.
* main/dovecot: Properly set primary group in .pre-install.
main/dovecot/dovecot.pre-install

* main/{npre,postgrey}: Properly set primary group in .pre-install.
main/nrpe/nrpe.pre-install
main/postgrey/postgrey.pre-install

* main/ympd: Reorder arguments in .pre-install as in da4e96aacef5.
main/ympd/ympd.pre-install

* main/znc: Reorder arguments in .pre-install as in da4e96aacef5.
main/znc/znc.pre-install

* main/aports-build: Reorder arguments in .pre-install as in da4e96aacef5.
main/aports-build/aports-build.pre-install

* main/atheme-iris: Fix overlooked consistency issue as in a60b9f07dee0.
main/atheme-iris/atheme-iris.pre-install

* main/[various]: Add group and use it as primary in .pre-* scripts.
main/apache2/apache2.pre-install
main/aports-build/aports-build.pre-install
main/atheme-iris/atheme-iris.pre-install
main/clamav/clamav-db.pre-install
main/clamsmtp/clamsmtp.pre-install
main/clamsmtp/clamsmtp.pre-upgrade
main/coova-chilli/coova-chilli.pre-install
main/dhcp/dhcp.pre-install
main/djbdns/dnscache.pre-install
main/djbdns/tinydns.pre-install
main/ez-ipupdate/ez-ipupdate.pre-install
main/fetchmail/fetchmail.pre-install
main/freeswitch/freeswitch.pre-install
main/gitolite/gitolite.pre-install
main/gnats/gnats.pre-install
main/gross/gross.pre-install
main/icecast/icecast.pre-install
main/memcached/memcached.pre-install
main/ngircd/ngircd.pre-install
main/openntpd/openntpd.pre-install
main/snort/snort.pre-install
main/squid/squid.pre-install
main/squid/squid.pre-upgrade
main/transmission/transmission-daemon.pre-install
main/znc/znc.pre-install
2016-06-07 07:20:09 +00:00
Przemyslaw Pawelczyk
a7d67c695c main/[various]: Add group and use it as primary in .pre-* scripts.
Fixes the problem I unintentionally brought in commit ccc056dbf9d3:
system user creation doesn't add same named group and uses nogroup as
primary group unless explicitly specified via -G.

Brings status quo regarding primary groups of users created in packages:
- main/apache2
- main/aports-build
- main/atheme-iris
- main/clamav
- main/clamsmtp
- main/coova-chilli
- main/dhcp
- main/djbdns
- main/ez-ipupdate
- main/fetchmail
- main/freeswitch
- main/gitolite
- main/gnats
- main/gross
- main/icecast
- main/memcached
- main/ngircd
- main/openntpd
- main/snort
- main/squid
- main/transmission
- main/znc
2016-06-07 07:20:09 +00:00
Kaarle Ritvanen
693349646e main/apache2: upgrade to 2.4.20 2016-05-02 18:34:30 +03:00
steffen@stelas.de
35091c0926 main/apache2: recompile broken suEXEC
Fixing two issues regarding suEXEC:
- suEXEC compiles with correct Apache user
- set docroot to /var/www - needed for virtual hosts

ref #5500
2016-04-27 13:45:17 +00:00
Przemyslaw Pawelczyk
0f920d3abe main/[various]: bump pkgrel for pre-install fixes 2016-04-25 07:11:16 +00:00
Przemyslaw Pawelczyk
da4e96aace Reorder arguments passed to addgroup/adduser in scripts.
Now all invocations have following order of arguments (if present):

    addgroup -S -g ... GROUP
    adduser -S -u ... -D -H -h ... -s ... -G ... -g ... USER
2016-04-25 06:56:47 +00:00
Przemyslaw Pawelczyk
a60b9f07de Improve consistency of scripts using adduser/addgroup.
Following rules have been applied:
- script starts with shebang !#/bin/sh followed by blank line,
- script ends with exit 0 prepended by blank line,
- only stderr of adduser, addgroup or passwd is redirected to /dev/null,
- getent passwd/group instances has been removed,
- manual checking of file and group existence has been removed,
- `|| true` instances has been removed.

Comments and line wrapping have been preserved.
2016-04-25 06:55:43 +00:00
Przemyslaw Pawelczyk
a593d306c9 Add -g option (GECOS/comment) to adduser in scripts.
This way we can avoid ugly default:

    Linux user,,,
2016-04-25 06:54:18 +00:00
Przemyslaw Pawelczyk
ccc056dbf9 Add lacking -S option (system) to adduser/addgroup in scripts.
Groups and users created by packages shouldn't use high ids by default
(unless explicitly requested), to distinguish them from groups and users
created by administrators for humans.

Following 41 files lacked -S next to addgroup:
- community/sword/sword.pre-install
- main/amavisd-new/amavisd-new.pre-install
- main/chrony/chrony.pre-install
- main/cvechecker/cvechecker.pre-install
- main/dnsmasq/dnsmasq.pre-install
- main/freeradius/freeradius.pre-install
- main/gdnsd/gdnsd.pre-install
- main/haproxy/haproxy.pre-install
- main/haproxy/haproxy.pre-upgrade
- main/kamailio/kamailio.pre-install
- main/logcheck/logcheck.pre-install
- main/mlmmj/mlmmj.pre-install
- main/nrpe/nrpe.pre-install
- main/open-vm-tools/open-vm-tools.pre-install
- main/postgrey/postgrey.pre-install
- main/privoxy/privoxy.pre-install
- main/redis/redis.pre-install
- main/samba/winbind.pre-install
- main/sircbot/sircbot.pre-install
- main/smokeping/smokeping.pre-install
- main/squark/squark.post-install
- main/squid/squid.pre-install
- main/squid/squid.pre-upgrade
- main/subversion/subversion.pre-install
- main/trac/trac.pre-install
- main/vsftpd/vsftpd.pre-install
- main/zabbix/zabbix-agent.pre-install
- testing/3proxy/3proxy.pre-install
- testing/cluster-glue/cluster-glue.pre-install
- testing/elasticsearch/elasticsearch.pre-install
- testing/emby/emby.pre-install
- testing/gdnsd/gdnsd.pre-install
- testing/icinga2/icinga2.pre-install
- testing/lusca/lusca.pre-install
- testing/lusca/lusca.pre-upgrade
- testing/mongodb/mongodb.pre-install
- testing/openxcap/openxcap.pre-install
- testing/prosody/prosody.pre-install
- testing/rancid/rancid.pre-install
- testing/rutorrent/rutorrent.pre-install
- testing/zabbix/zabbix-agent.pre-install

Following 60 files lacked -S next to adduser:
- community/caddy/caddy.pre-install
- community/domoticz/domoticz.pre-install
- community/minetest/minetest-server.pre-install
- community/oscam/oscam.pre-install
- community/seafile/seafile-server.pre-install
- community/syncthing/syncthing.pre-install
- main/apache2/apache2.pre-install
- main/aports-build/aports-build.pre-install
- main/atheme-iris/atheme-iris.pre-install
- main/bind/bind.pre-install
- main/clamav/clamav-db.pre-install
- main/clamsmtp/clamsmtp.pre-install
- main/clamsmtp/clamsmtp.pre-upgrade
- main/coova-chilli/coova-chilli.pre-install
- main/cvechecker/cvechecker.pre-install
- main/dhcp/dhcp.pre-install
- main/distcc/distcc.pre-install
- main/djbdns/dnscache.pre-install
- main/djbdns/tinydns.pre-install
- main/dovecot/dovecot.pre-install
- main/ez-ipupdate/ez-ipupdate.pre-install
- main/fetchmail/fetchmail.pre-install
- main/freeswitch/freeswitch.pre-install
- main/gitolite/gitolite.pre-install
- main/gnats/gnats.pre-install
- main/gross/gross.pre-install
- main/icecast/icecast.pre-install
- main/kamailio/kamailio.pre-install
- main/lighttpd/lighttpd.pre-install
- main/mariadb/mariadb.pre-install
- main/memcached/memcached.pre-install
- main/ngircd/ngircd.pre-install
- main/nrpe/nrpe.pre-install
- main/openntpd/openntpd.pre-install
- main/postgrey/postgrey.pre-install
- main/snort/snort.pre-install
- main/squid/squid.pre-install
- main/squid/squid.pre-upgrade
- main/subversion/subversion.pre-install
- main/trac/trac.pre-install
- main/transmission/transmission-daemon.pre-install
- main/ympd/ympd.pre-install
- main/znc/znc.pre-install
- testing/at/at.pre-install
- testing/buildbot-slave/buildbot-slave.pre-install
- testing/buildbot/buildbot.pre-install
- testing/clapf/clapf.pre-install
- testing/cluster-glue/cluster-glue.pre-install
- testing/dbmail/dbmail.pre-install
- testing/dspam/dspam.pre-install
- testing/ejabberd/ejabberd.pre-install
- testing/emby/emby.pre-install
- testing/mongodb/mongodb.pre-install
- testing/opensips/opensips.pre-install
- testing/pdns/pdns.pre-install
- testing/prosody/prosody.pre-install
- testing/qpage/qpage.pre-install
- testing/rrdbot/rrdbot.pre-install
- testing/wt/wt.pre-install
- unmaintained/ejabberd-git/ejabberd-git.pre-install
2016-04-25 06:53:54 +00:00
Przemyslaw Pawelczyk
694ace841f Reorder options passed to addgroup in scripts: make -S first.
It's only for consistency and to ease spotting lack of it.
2016-04-25 06:51:49 +00:00
Kaarle Ritvanen
701b5621b4 main/apache2: upgrade to 2.4.18 2016-02-15 21:48:50 +02:00
Kaarle Ritvanen
6eeb5be5d8 main/apache2: fix indented LoadModule paths 2016-02-15 17:34:22 +02:00